Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to read and write local files and fetch external sources in real time, yet no explicit permission model is declared. That mismatch creates hidden capability escalation risk: a caller or host may assume this is a low-privilege content skill when it is actually designed to access the filesystem and network extensively.
